Dfinitive Logo
+27765215042
info@d-finitive.com
When ransomware strikes, the decisions made in the first 24 hours can shape everything that follows. From containing the attack and preserving digital evidence to maintaining business continuity, discover why preparation, decisive leadership and cyber resilience matter long before the first system is encrypted.

Ransomware: What Every Organisation Should Do in the First 24 Hours

The Day Everything Stops

It begins with what appears to be an ordinary working day.

 

Employees arrive at the office, switch on their computers and prepare for another day of business. Within minutes, the first calls start coming through. Shared drives cannot be accessed. Critical business applications fail to load. Customer records have disappeared, accounting systems are unavailable and emails begin flooding the IT department reporting the same problem.

 

Then the message appears.

 

Your files have been encrypted.

 

To recover your data, follow the payment instructions below.

 

In an instant, normal business operations grind to a halt.

 

For many organisations, the immediate reaction is panic. Questions arise faster than answers. Has customer information been compromised? Should the ransom be paid? Who needs to be informed? Can the business continue operating? Is this simply an information technology incident, or has it become a full-scale organisational crisis? What are the potential regulatory risks and penalties for POPPI breaches?

 

These are not decisions that can be deferred until tomorrow. The first 24 hours following a ransomware attack are often the most critical. The actions taken—or not taken—during this period can significantly influence the extent of financial losses, operational disruption, legal exposure and the organisation's ability to recover.

 

Ransomware is no longer simply a cybersecurity issue. It is a business resilience challenge that demands decisive leadership, coordinated incident response and disciplined decision-making. Organisations that respond methodically are far more likely to contain the damage, preserve critical evidence and restore operations than those that react impulsively under pressure.

 

The true measure of resilience is not whether an organisation experiences a cyberattack—it is how effectively it responds when the attack occurs.

 

The First 24 Hours Matter Most

When ransomware strikes, every minute feels critical. The instinct to restore systems immediately, negotiate with the attackers or simply "fix the problem" is understandable. However, decisions made in haste can unintentionally worsen the situation, destroy valuable forensic evidence or prolong the organisation's recovery.

 

The first priority is containment. Affected systems should be isolated from the network as quickly as possible to limit the spread of the malware. At the same time, organisations should activate their incident response plan, assemble the appropriate internal stakeholders and establish a coordinated approach to managing the crisis. Ransomware is rarely confined to the IT department—it quickly becomes an operational, legal, financial and reputational issue that requires executive oversight.

 

Equally important is preserving evidence. While restoring systems may seem like the logical first step, understanding how the attackers gained access is critical to preventing a second compromise. Log files, affected devices and system images may provide investigators with valuable evidence regarding the attack vector, the scope of the compromise and whether sensitive information was accessed or exfiltrated before encryption occurred.

 

Communication also plays a vital role during the early stages of an incident. Employees require clear guidance on what has happened, what actions they should avoid and how business operations will continue while systems are being restored. Where customers, regulators or other stakeholders may be affected, organisations should ensure that communications are accurate, timely and coordinated. Poor communication can damage confidence just as quickly as the cyberattack itself.

 

The first 24 hours are not about making every decision—they are about making the right decisions. Organisations that remain calm, follow established incident response procedures and preserve evidence are far better positioned to contain the attack, support forensic investigations and recover with confidence

 

Lessons from a Global Ransomware Attack

In February 2024, one of the world's largest healthcare technology providers, Change Healthcare, suffered a ransomware attack that disrupted healthcare services across the United States. Pharmacies experienced delays in processing prescriptions, healthcare providers struggled to submit insurance claims, and millions of patients were affected as critical systems became unavailable. The incident demonstrated how a single cyberattack could rapidly escalate into a nationwide operational crisis affecting organisations far beyond the original victim. (UnitedHealth Group, 2024; CISA, 2024).

 

Investigations revealed that the attack had consequences extending well beyond encrypted systems. Business operations were interrupted for weeks, recovery costs escalated significantly, and the organisation faced regulatory scrutiny, legal challenges and reputational damage. Reports later indicated that the attackers had also exfiltrated sensitive data before deploying the ransomware, highlighting that modern ransomware attacks are increasingly driven by both operational disruption and data extortion. (UnitedHealth Group, 2024; Reuters, 2024).

 

The Change Healthcare incident reinforces an important lesson for every organisation: ransomware is no longer simply about restoring encrypted files. It is about protecting business continuity, preserving stakeholder confidence and ensuring that critical services can continue during a crisis. Organisations that focus solely on recovering their systems often overlook the broader governance, legal and operational challenges that follow a significant cyber incident.

 

South Africa has experienced its own reminders of how cyber incidents can disrupt critical services and expose organisations to significant operational and information-security risks. In June 2024, the National Health Laboratory Service (NHLS), which provides diagnostic pathology services to the public healthcare sector, suffered a ransomware attack that rendered parts of its information technology environment inaccessible and disrupted the electronic communication of laboratory results to healthcare facilities. The NHLS activated its incident response team while laboratories continued processing clinical samples and urgent results were communicated telephonically (SA News, 2024; Cassim & Chapanduka, 2024).

 

South Africa's financial and credit ecosystem has faced different but equally instructive data-security incidents. In 2020, credit bureau Experian experienced a fraudulent data incident that the Information Regulator subsequently reported had exposed some personal information relating to as many as 24 million South Africans and 793,749 business entities. The Regulator's investigation found that the incident arose after Experian entered into a commercial engagement with an individual misrepresenting themselves as a director of a legitimate company (Information Regulator, 2021) (Experian South Africa, 2020).

 

Although these incidents differ in method and impact, they reinforce a common lesson: organisations responsible for critical services and large volumes of personal information require effective incident-response arrangements, strong information governance and tested business-continuity measures.

 

For executives and boards, the lesson is clear. An effective response cannot begin when the ransom note appears. It starts long before an attack occurs through incident response planning, tested business continuity arrangements, regular backups, executive decision-making protocols and clearly defined communication strategies. The organisations that recover most effectively are rarely those with the best technology alone—they are those that have prepared for the possibility that technology may fail.


Cyber Resilience Begins Before the Attack

Ransomware is often described as a cybersecurity incident, but its consequences extend far beyond information technology. It can disrupt operations, interrupt customer services, expose sensitive information and place significant financial, legal and reputational pressure on an organisation. Responding effectively therefore requires far more than technical expertise—it requires leadership, preparation and coordinated decision-making.

 

Cyber resilience is built long before an attack occurs. Organisations should maintain tested incident response and business continuity plans, perform regular offline backups, clearly define roles and responsibilities during a cyber incident, and ensure employees understand how to recognise and report suspicious activity. Equally important is preserving digital evidence and understanding how the attack occurred before restoring affected systems, reducing the likelihood of a repeat compromise.

 

No organisation can guarantee that it will never experience a ransomware attack. However, every organisation can decide how well prepared it will be when one occurs. The difference between a temporary disruption and a prolonged business crisis is often determined long before the first system is encrypted.

 

D-finitive Insight

Ransomware is no longer simply an information technology issue—it is a business resilience challenge requiring coordinated leadership across governance, risk management, information security, legal, operations and executive management.

 

At D-finitive Advisory, our experience has consistently shown that organisations recover more effectively when cyber resilience forms part of their broader governance framework rather than being viewed solely as a technical responsibility. Effective preparation combines strong governance, clearly defined incident response procedures, tested business continuity arrangements, digital forensic readiness and informed decision-making at every level of the organisation.

 

The organisations that emerge strongest from a cyber incident are rarely those with the largest technology budgets. They are the organisations that prepare, respond decisively and continuously strengthen their resilience against future threats.

 

Delivering Clarity. Protecting Integrity. Driving Accountability.